Impact
A missing authorization check in the Navneil Naicker ACF Galerie 4 WordPress plugin allows an attacker to perform privileged actions or retrieve protected content that should otherwise be inaccessible, corresponding to CWE‑862. The flaw carries a CVSS score of 4.3, indicating moderate risk, and the description explicitly notes that incorrectly configured access control security levels can be exploited.
Affected Systems
The vulnerability affects the Navneil Naicker ACF Galerie 4 plugin for WordPress versions up to and including 1.4.2; all earlier versions are also impacted though the boundary is not precisely delineated beyond 1.4.2. Site owners should verify the installed version and apply the upgrade as soon as possible.
Risk and Exploitability
The CVSS score of 4.3 reflects a moderate potential impact. The EPSS score of less than 1% indicates very low to negligible exploitation probability in the wild, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is the plugin’s administrative or data retrieval endpoints where the authorization gate is bypassed; however, the description does not provide explicit details on the exact exploitation method.
OpenCVE Enrichment